GDPR compliance does not need to be a binder of documents nobody reads. What it needs is an honest map of the personal data you hold, a lawful reason for each use, sensible security, and documents that reflect what the business really does. That is what a regulator, an investor or a corporate customer will ask to see.
How we work
Audit
We map data flows across your systems, suppliers and staff, and identify gaps against the GDPR and the Bulgarian Personal Data Protection Act.
Documentation
Privacy notices, internal policies, records of processing activities, consent and retention rules.
Contracts
Data processing agreements with suppliers, joint-controller arrangements and safeguards for transfers outside the EEA.
High-risk processing
Data protection impact assessments where monitoring, health data or large-scale processing is involved.
Incidents and enquiries
Breach response, notifications, data subject requests, and representation before the Commission for Personal Data Protection.
- Compliance reviews against the GDPR and the Bulgarian Personal Data Protection Act
- Privacy notices for customers, staff and website visitors
- Internal policies, retention schedules and the processing register
- Impact assessments for high-risk processing
- Contracts with processors and joint controllers
- Advice on whether to appoint a DPO — and whom
- Breach response, complaints and inspections before the CPDP
Questions clients ask
Does my company need a data protection officer?
Under Art. 37 GDPR a DPO is mandatory for public bodies, and for organisations whose core activities involve large-scale regular and systematic monitoring of individuals or large-scale processing of special categories of data, such as health or biometric data. Others may appoint one voluntarily. The DPO can be an employee or an external provider.
How large can GDPR fines be?
For the most serious breaches, up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher. In Bulgaria fines are imposed by the Commission for Personal Data Protection. Individuals can also claim compensation for material and non-material damage caused by an infringement.